MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5515ac192cad8082350a7c5f3713c2728d1743f2f4f02ac3118938b78571b064. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 17
| SHA256 hash: | 5515ac192cad8082350a7c5f3713c2728d1743f2f4f02ac3118938b78571b064 |
|---|---|
| SHA3-384 hash: | 6ba123bde50c9b100bac6d50f83283d79e30a6ff5200121483f4fe73485463a5f351db678ae43b40535a159ee9377d1a |
| SHA1 hash: | 9f1247ef3e49b40b9d75db5ecd896423860405e7 |
| MD5 hash: | 2311414304c21597111eb2240803b775 |
| humanhash: | lamp-mexico-single-earth |
| File name: | file |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 347'648 bytes |
| First seen: | 2023-07-14 01:10:54 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | b1bd1e1b3d820b60a26549b25bdb6ca5 (2 x RedLineStealer, 1 x TeamBot) |
| ssdeep | 6144:FSijXWVebq+BF8CQ3tBwOAD64UOJZwhwDk87QYlkk8:F7jXWVGFj8ztBwLD6OJuV87lu |
| Threatray | 218 similar samples on MalwareBazaar |
| TLSH | T1AB74D10237B1A430E1A646314D7BD6E52A2FFDA18F6856FB3B043A2F1D702D18976F52 |
| TrID | 52.5% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 17.7% (.EXE) Win64 Executable (generic) (10523/12/4) 8.4% (.EXE) Win16 NE executable (generic) (5038/12/1) 7.5% (.EXE) Win32 Executable (generic) (4505/5/1) 3.4% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | 002060b094622100 (1 x RedLineStealer) |
| Reporter | |
| Tags: | exe RedLineStealer |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
c72a8287f05afce5b508575b2a85bdf624b19b55b0e25d75861e6d7f335ed62b
77c00490ef21b0676ee43ed686265e6ccdc77a705f2d1985e3c16e8cd063d1ab
58135dd77a183a9831ea6846925abed077fed0b2b0dd554f97dc37beac520bff
e80b5b33c6819e99db81c1851f5cd5489ccd0b73e6a9d859a1e3ff16f6904c47
34e583d49b9e513fbd9782feb5d0ff3752f4468c77a012f776fda29cc7630425
058d85c10de17415e2a2e98c8e0bbaebcc6115f62bf58b2b4463d6a57f894ff4
95084eb619f87c93ad143700f298dc5525c2a0520c308b69411518a9754dc3a5
34e786b9788e2c0e8626bfdcf63d8452f9a828cc8ce4638b1097a706ba3d99c5
198d358130add33c5437dc1395c40dc82674117d83b3de8ed34c18e219bb772d
b7fb42f9010350a5017a98030aa63fea68110dcfda54f4be7e41e71436bbc19d
340282e2d371b086effe7b5101c29177b0ce824e66a47bbd614201b66d206e0d
dfc89c3dc2c053da90b7318a6d79bbd9002f74169dcd257f39e7c05e6152e2e5
cf3e311e4da4c2ccb76ef52bef85ae1f1445184b003238767df463f94b10067c
b2cf54a448abb2f1d88d9c121ff0687c670d48da1656ab8f0c3902d12b02f586
39e3c3ce776a11b90a9d65fb2e9b2a864a67f4ea0f630eaf54f800f71214941f
2c03c9e1501d701df9469d254016cecab85954bddbf2a4f77b38ef361b6d2a84
64d4cb3a5b533e0cfee82a3f2f4501465bfe45247d02ccfa995251bcf973b742
dfe1b2d706af16a41a5fd06259b9a7c892ec9e35803831c03099a05da6d7250c
13a0e3fab615c90709fc8c5c16ff2654536cd67eb68d39f0f3d1b65e192e028c
15813ccb11cc4944c5d768d69c2896e38f3e42bd0de92f8cc1ba7a70fab7e2b7
c60d7dbb56c7ee282684d03a3665b50ed66037631677cf5afb53fccd18e2bca7
58d88633b18ed9a6f8a1836c4a14a57f0d2d0649313863b29157cb7c2aa1f1a5
9b64b300f3779a2e1f6e34e415cca45d63387336d62d0a5d4bfb86d281102156
789a59f4302507e7f2ffac7eb0beaadb492f4f8066f789473257324f92ebfca4
ff3b2c0b18f7eb7ed3d1cfed0ae43b2455a344abb011d12b52ed0f4b05ed1860
ca3c6a4c08e5fab0105dc5ac39ebfa918be5ad7a2a75d89792e857597b609952
7868e7c5e31315e7bb442bafbbc16addfeb4bda998b404491976aa271fbb78ef
d75ea0128a4ccf483451f76df058a129f563a281f4a760287e7593da451958c1
d8c40594c29b4d9ca99a0e2f7100b4d22180d2d19ef8ac9b7c5f3a543a9ab799
147f3bc8497061adebffb891a2ed8d33aa8f6d9332278f5950e624a45100eaa3
64be0b226a3702b84017179478cff58423ee83124721208c035b4f80177fe4d0
2e2cb986f32eb3b75f8b9e3a787d5670f33a5468bdf4fa3151d8e7f55977e2b1
32657b4963e9bce965803336169d4a69c3271f4baa9844ecbdba51d937be3616
43f44d1e80d8421ea6b06c309585a81034992d4fd2b4135c199ddbcbbf4e9495
853621a1b8acd0226410a62db92e63dacdf23b77a7bfdb17ac87b72ea8beb1e8
75ee0bdad2dbc7c371d3b0c8224acf01a7b30fc3f5095589aee76ead64bb9b85
07ba061bc6568fd1b753454ab7ed979d17c4945ff77751d50230dc5f200b02d3
fe60020a4943d4ef55b6241463d202e1e74a97d54da1375f4346861e9f36d556
9b47dfbcf99f7aae8f2a12149436ccf0f737f7f6d4e4ec412a17414bf3fdc53e
2eaa3a926521c39de1c263a45f8eae4f317e211816ab0d3683bd05423a6510c0
dfe9bcd743ab31777f656a5c65f2daf14b63a6b719f40cced0ee958219caa320
fd008edf8d8d15020bd74272c225e5861c863b0bd0a7653a1abf4f02746a2c2d
5515ac192cad8082350a7c5f3713c2728d1743f2f4f02ac3118938b78571b064
7e332993bb155e096895d26b3a6f86e950bb4909d32ef450dd6e45726de5e7e6
13e526453c77926484bcbee2aad76c7924fbc18abebb34b0c53be6fb8d2d1adb
cb3ac138a95f47f3b266efc13b2bb8371d96920b4b31446a84a2e7dc10926c51
a2cdcfd9280311961c242775c66f3f731242a31813b5893214646a1f2f2d692f
e56230dc9ff93a3321313d8eec5785f966ae843da7d7be6cc17fc91c113453a5
849bf41e6f85ebf58c629799ccf7d1bc5cad554d5a96f5be9c683f09d929d802
4726f703d20686183cf84175978a96b4e411f472073c802a76ce903ab67ff50f
15152abb9383b48525667c7d275d79ef5c333195caeeccd98517e73728963e95
fadf49176490c92667325c5051cf09e517df5405c10dd862a8940d2e38042e14
9dcdfb17d806e535f4310517dbc3a23fad35279119b608a6de05a2b13be467ed
5ce5071790c2e83ffc59fc291021f55f1e200bfd63033f17ed80320940f9b1a7
c72a8287f05afce5b508575b2a85bdf624b19b55b0e25d75861e6d7f335ed62b
77c00490ef21b0676ee43ed686265e6ccdc77a705f2d1985e3c16e8cd063d1ab
58135dd77a183a9831ea6846925abed077fed0b2b0dd554f97dc37beac520bff
e80b5b33c6819e99db81c1851f5cd5489ccd0b73e6a9d859a1e3ff16f6904c47
34e583d49b9e513fbd9782feb5d0ff3752f4468c77a012f776fda29cc7630425
058d85c10de17415e2a2e98c8e0bbaebcc6115f62bf58b2b4463d6a57f894ff4
95084eb619f87c93ad143700f298dc5525c2a0520c308b69411518a9754dc3a5
34e786b9788e2c0e8626bfdcf63d8452f9a828cc8ce4638b1097a706ba3d99c5
198d358130add33c5437dc1395c40dc82674117d83b3de8ed34c18e219bb772d
b7fb42f9010350a5017a98030aa63fea68110dcfda54f4be7e41e71436bbc19d
340282e2d371b086effe7b5101c29177b0ce824e66a47bbd614201b66d206e0d
dfc89c3dc2c053da90b7318a6d79bbd9002f74169dcd257f39e7c05e6152e2e5
cf3e311e4da4c2ccb76ef52bef85ae1f1445184b003238767df463f94b10067c
b2cf54a448abb2f1d88d9c121ff0687c670d48da1656ab8f0c3902d12b02f586
39e3c3ce776a11b90a9d65fb2e9b2a864a67f4ea0f630eaf54f800f71214941f
2c03c9e1501d701df9469d254016cecab85954bddbf2a4f77b38ef361b6d2a84
64d4cb3a5b533e0cfee82a3f2f4501465bfe45247d02ccfa995251bcf973b742
dfe1b2d706af16a41a5fd06259b9a7c892ec9e35803831c03099a05da6d7250c
13a0e3fab615c90709fc8c5c16ff2654536cd67eb68d39f0f3d1b65e192e028c
15813ccb11cc4944c5d768d69c2896e38f3e42bd0de92f8cc1ba7a70fab7e2b7
c60d7dbb56c7ee282684d03a3665b50ed66037631677cf5afb53fccd18e2bca7
58d88633b18ed9a6f8a1836c4a14a57f0d2d0649313863b29157cb7c2aa1f1a5
9b64b300f3779a2e1f6e34e415cca45d63387336d62d0a5d4bfb86d281102156
789a59f4302507e7f2ffac7eb0beaadb492f4f8066f789473257324f92ebfca4
ff3b2c0b18f7eb7ed3d1cfed0ae43b2455a344abb011d12b52ed0f4b05ed1860
ca3c6a4c08e5fab0105dc5ac39ebfa918be5ad7a2a75d89792e857597b609952
7868e7c5e31315e7bb442bafbbc16addfeb4bda998b404491976aa271fbb78ef
d75ea0128a4ccf483451f76df058a129f563a281f4a760287e7593da451958c1
d8c40594c29b4d9ca99a0e2f7100b4d22180d2d19ef8ac9b7c5f3a543a9ab799
147f3bc8497061adebffb891a2ed8d33aa8f6d9332278f5950e624a45100eaa3
64be0b226a3702b84017179478cff58423ee83124721208c035b4f80177fe4d0
2e2cb986f32eb3b75f8b9e3a787d5670f33a5468bdf4fa3151d8e7f55977e2b1
32657b4963e9bce965803336169d4a69c3271f4baa9844ecbdba51d937be3616
43f44d1e80d8421ea6b06c309585a81034992d4fd2b4135c199ddbcbbf4e9495
853621a1b8acd0226410a62db92e63dacdf23b77a7bfdb17ac87b72ea8beb1e8
75ee0bdad2dbc7c371d3b0c8224acf01a7b30fc3f5095589aee76ead64bb9b85
07ba061bc6568fd1b753454ab7ed979d17c4945ff77751d50230dc5f200b02d3
fe60020a4943d4ef55b6241463d202e1e74a97d54da1375f4346861e9f36d556
9b47dfbcf99f7aae8f2a12149436ccf0f737f7f6d4e4ec412a17414bf3fdc53e
2eaa3a926521c39de1c263a45f8eae4f317e211816ab0d3683bd05423a6510c0
dfe9bcd743ab31777f656a5c65f2daf14b63a6b719f40cced0ee958219caa320
fd008edf8d8d15020bd74272c225e5861c863b0bd0a7653a1abf4f02746a2c2d
5515ac192cad8082350a7c5f3713c2728d1743f2f4f02ac3118938b78571b064
7e332993bb155e096895d26b3a6f86e950bb4909d32ef450dd6e45726de5e7e6
13e526453c77926484bcbee2aad76c7924fbc18abebb34b0c53be6fb8d2d1adb
cb3ac138a95f47f3b266efc13b2bb8371d96920b4b31446a84a2e7dc10926c51
a2cdcfd9280311961c242775c66f3f731242a31813b5893214646a1f2f2d692f
e56230dc9ff93a3321313d8eec5785f966ae843da7d7be6cc17fc91c113453a5
849bf41e6f85ebf58c629799ccf7d1bc5cad554d5a96f5be9c683f09d929d802
4726f703d20686183cf84175978a96b4e411f472073c802a76ce903ab67ff50f
15152abb9383b48525667c7d275d79ef5c333195caeeccd98517e73728963e95
fadf49176490c92667325c5051cf09e517df5405c10dd862a8940d2e38042e14
9dcdfb17d806e535f4310517dbc3a23fad35279119b608a6de05a2b13be467ed
5ce5071790c2e83ffc59fc291021f55f1e200bfd63033f17ed80320940f9b1a7
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | MAL_Malware_Imphash_Mar23_1 |
|---|---|
| Author: | Arnim Rupp |
| Description: | Detects malware by known bad imphash or rich_pe_header_hash |
| Reference: | https://yaraify.abuse.ch/statistics/ |
| Rule name: | Windows_Trojan_Smokeloader_3687686f |
|---|---|
| Author: | Elastic Security |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.